Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.5
CVE-2026-15996
A denial of service vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to cause excessive CPU consumpt…
Enterprise Server
No fix yet
CRITICAL 9.1
CVE-2026-17556
A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to delete arbitrary files and dire…
Enterprise Server
No fix yet
HIGH 7.5
CVE-2026-47427
GitHub MCP Server is GitHub's official MCP Server. Prior to 1.1.0, the CompletionsHandler function in pkg/github/server.go accesses params.Ref withou…
Mcp Server
1.1.0+
MEDIUM 5.0
CVE-2026-14340
An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed a user-to-server token scoped to a GitHub App instal…
Enterprise Server
3.16.20 / 3.17.17+
MEDIUM 5.4
CVE-2026-10585
A stored cross-site scripting vulnerability was identified in GitHub Enterprise Server that allowed an authenticated attacker to execute arbitrary Ja…
Enterprise Server
3.16.20 / 3.17.17+
MEDIUM 6.5
CVE-2026-9132
A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user to read source code from private …
Enterprise Server
3.17.17 / 3.18.11+
MEDIUM 5.5
CVE-2026-9106
A UI misrepresentation vulnerability was identified in GitHub Enterprise Server that allowed an OAuth application to gain unintended access to an org…
Enterprise Server
3.16.20 / 3.17.17+
CRITICAL 9.1
CVE-2026-48501
GitHub CLI (gh) is GitHub’s official command line tool. Prior to 2.93.0, GitHub CLI incorrectly includes authorization header in API requests to TUF …
Cli
2.93.0+
HIGH 8.2
CVE-2026-9312EPSS 7%
A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to send crafte…
Enterprise Server
3.16.19 / 3.17.16+
MEDIUM 5.9
CVE-2026-8606
A Server-Side Request Forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an attacker to cause the server to issue H…
Enterprise Server
3.16.19 / 3.17.16+
HIGH 7.8
CVE-2026-45033
GitHub Copilot CLI brings AI-powered coding assistance directly to your command line. Prior to 1.0.43, a security vulnerability has been identified …
Copilot Cli
1.0.43+
CRITICAL 9.8
CVE-2026-8034
A server-side request forgery (SSRF) vulnerability was identified in the GitHub Enterprise Server notebook viewer that allowed an attacker to access …
Enterprise Server
3.16.18 / 3.17.15+
MEDIUM 6.1
CVE-2026-8106
A reflected HTML injection vulnerability was identified in the GitHub Enterprise Server Management Console login page that could allow credential the…
Enterprise Server
3.19.6 / 3.20.2+
HIGH 7.5
CVE-2026-7541
A denial of service vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to cause service disruption by …
Enterprise Server
3.16.18 / 3.17.15+
MEDIUM 6.5
CVE-2026-6736
An authentication bypass vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to create a local user acc…
Enterprise Server
3.16.18 / 3.17.15+
CRITICAL 9.6
CVE-2026-5845
An improper authorization vulnerability in scoped user-to-server (ghu_) token authorization in GitHub Enterprise Server allows an authenticated attac…
Enterprise Server
3.14.26 / 3.15.21+
HIGH 8.9
CVE-2026-5921
A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an attacker to extract sensitive environme…
Enterprise Server
3.14.26 / 3.15.21+
HIGH 8.8
CVE-2026-4296
An incorrect regular expression vulnerability was identified in GitHub Enterprise Server that allowed an attacker to bypass OAuth redirect URI valida…
Enterprise Server
3.14.26 / 3.15.21+
MEDIUM 5.4
CVE-2026-2266
An improper neutralization of input vulnerability was identified in GitHub Enterprise Server that allowed DOM-based cross-site scripting via task lis…
Enterprise Server
3.18.6 / 3.19.3+
HIGH 8.8
CVE-2026-3854EPSS 34%
An improper neutralization of special elements vulnerability was identified in GitHub Enterprise Server that allowed an attacker with push access to …
Enterprise Server
3.14.24 / 3.15.19+
HIGH 7.8
CVE-2026-29783
The shell tool within GitHub Copilot CLI versions prior to and including 0.0.422 can allow arbitrary code execution through crafted bash parameter ex…
Copilot Command Line Interface
0.0.423+
MEDIUM 6.5
CVE-2026-1999
An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed an attacker to merge their own pull request into a r…
Enterprise Server
3.17.11 / 3.18.5+
MEDIUM 6.5
CVE-2026-1355
A Missing Authorization vulnerability was identified in GitHub Enterprise Server that allowed an attacker to upload unauthorized content to another u…
Enterprise Server
3.14.23 / 3.15.18+
CRITICAL 9.0
CVE-2026-0573
An URL redirection vulnerability was identified in GitHub Enterprise Server that allowed attacker-controlled redirects to leak sensitive authorizatio…
Enterprise Server
3.14.22 / 3.15.17+
MEDIUM 5.4
CVE-2025-13744
An Improper Neutralization of Input During Web Page Generation vulnerability was identified in GitHub Enterprise Server that allowed attacker control…
Enterprise Server
3.14.20 / 3.15.15+
MEDIUM 6.1
CVE-2025-14046
An improper neutralization of input vulnerability was identified in GitHub Enterprise Server that allowed user-supplied HTML to inject DOM elements w…
Enterprise Server
3.14.21 / 3.15.16+
CRITICAL 9.6
CVE-2025-11892
An improper neutralization of input vulnerability was identified in GitHub Enterprise Server that allows DOM-based cross-site scripting via Issues se…
Enterprise Server
3.14.19 / 3.15.14+
HIGH 7.2
CVE-2025-11578
A privilege escalation vulnerability was identified in GitHub Enterprise Server that allowed an authenticated Enterprise admin to gain root SSH acces…
Enterprise Server
3.14.20 / 3.15.15+
HIGH 7.6
CVE-2025-3246
An improper neutralization of input vulnerability was identified in GitHub Enterprise Server that allowed cross-site scripting in GitHub Markdown tha…
Enterprise Server
Mitigation only
HIGH 7.2
CVE-2025-3509
A Remote Code Execution (RCE) vulnerability was identified in GitHub Enterprise Server that allowed attackers to execute arbitrary code by exploiting…
Enterprise Server
3.13.16 / 3.14.13+